Oval Definition:oval:com.ubuntu.bionic:def:201575750000000
Revision Date:2016-01-09Version:1
Title:CVE-2015-7575 on Ubuntu 18.04 LTS (bionic) - medium.
Description:Mozilla Network Security Services (NSS) before 3.20.2, as used in Mozilla Firefox before 43.0.2 and Firefox ESR 38.x before 38.5.2, does not reject MD5 signatures in Server Key Exchange messages in TLS 1.2 Handshake Protocol traffic, which makes it easier for man-in-the-middle attackers to spoof servers by triggering a collision.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2015-7575
Platform(s):Ubuntu 18.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 18.04 LTS (bionic) is installed.
  • AND Package Information
  • firefox package in bionic was vulnerable but has been fixed (note: '43.0.4+build3-0ubuntu1').
  • OR gnutls28 package in bionic, is related to the CVE in some way and has been fixed (note: '3.3.18-1ubuntu1').
  • OR mbedtls package in bionic, is related to the CVE in some way and has been fixed (note: '2.2.1-2').
  • OR nss package in bionic, is related to the CVE in some way and has been fixed (note: '2:3.21-1ubuntu2').
  • OR openjdk-8 package in bionic, is related to the CVE in some way and has been fixed (note: '8u72-b15-1').
  • OR openssl package in bionic, is related to the CVE in some way and has been fixed (note: '1.0.2e-1ubuntu1').
  • OR thunderbird package in bionic was vulnerable but has been fixed (note: '1:38.6.0+build1-0ubuntu1').
  • BACK